[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2009:1203-01 -- Redhat subversion

ID: oval:org.secpod.oval:def:500580Date: (C)2012-01-31   (M)2021-06-02
Class: PATCHFamily: unix




Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Matt Lewis, of Google, reported multiple heap overflow flaws in Subversion when parsing binary deltas. A malicious user with commit access to a server could use these flaws to cause a heap overflow on that server. A malicious server could use these flaws to cause a heap overflow on a client when it attempts to checkout or update. These heap overflows can result in a crash or, possibly, arbitrary code execution. All Subversion users should upgrade to these updated packages, which contain a backported patch to correct these issues. After installing the updated packages, the Subversion server must be restarted for the update to take effect: restart httpd if you are using mod_dav_svn, or restart svnserve if it is used.

Platform:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Product:
subversion
Reference:
RHSA-2009:1203-01
CVE-2009-2411
CVE    1
CVE-2009-2411
CPE    3
cpe:/a:apache:subversion
cpe:/o:redhat:enterprise_linux:5
cpe:/o:redhat:enterprise_linux:4

© SecPod Technologies